Privacy Policy

Last updated: September 8, 2026

1. Introduction

MailBridge ("we", "us", or "our") provides an email migration service that helps users transfer email data between providers such as Gmail, Outlook, and other IMAP-compatible services. This Privacy Policy explains how we collect, use, and protect your information when you use our service.

2. Information We Collect

2.1 Account Information

When you create a MailBridge account, we collect:

  • Email address (for authentication and communication)
  • Display name (from your identity provider)
  • Authentication credentials (managed by Supabase Auth)

2.2 OAuth Tokens

When you connect your email accounts (Gmail, Outlook, etc.), we receive OAuth tokens that grant us access to your email data. These tokens are:

  • Encrypted at rest using AES-256-GCM encryption
  • Used only for migration — to read emails from your source account and write them to your destination account
  • Revocable at any time — you can disconnect your accounts from the dashboard, which deletes stored tokens

2.3 Email Data

During a migration, email messages pass through our system in real-time. We do not store email content (bodies, attachments, headers) in our database. The system operates as a pass-through: reading from the source and writing to the destination.

We do store:

  • Message metadata (Message-ID, subject, date) for idempotency tracking and duplicate prevention
  • Migration job status and progress information
  • Error logs for debugging failed transfers

2.4 Usage Data

We collect basic usage data to improve our service:

  • Migration job counts and completion rates
  • Error rates and types
  • Feature usage patterns

3. How We Use Your Information

  • To provide the migration service: Transfer your emails between providers as requested
  • To maintain reliability: Track migration progress, prevent duplicates, and recover from failures
  • To communicate with you: Send migration completion notifications and important service updates
  • To improve our service: Analyze usage patterns to improve reliability and performance

4. Data Sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. We share data only:

  • With email providers (Google, Microsoft) as necessary to perform migrations
  • With our infrastructure providers (Supabase, Vercel, Trigger.dev) who process data on our behalf under strict data protection agreements
  • When required by law

5. Data Security

  • OAuth tokens are encrypted at rest using AES-256-GCM
  • All data transfer uses TLS/HTTPS encryption
  • Database access is protected by Row Level Security (RLS)
  • We follow the principle of least privilege for all system access

6. Data Retention

  • OAuth tokens: retained until you disconnect the account or delete your MailBridge account
  • Migration metadata: retained for 90 days after migration completion
  • Error logs: retained for 30 days for debugging purposes

7. Your Rights

You have the right to:

  • Access your data — view connected accounts and migration history
  • Delete your data — disconnect accounts or delete your MailBridge account
  • Revoke OAuth access — at any time through the dashboard or directly through Google/Microsoft
  • Export your data — request a copy of your migration history

8. Children's Privacy

Our service is not directed to children under 13. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the service.

10. Contact Us

If you have questions about this Privacy Policy, please contact us at: